VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2021-28446HigApr 13, 2021
    risk 0.46cvss 7.1epss 0.01

    Windows Portmapping Information Disclosure Vulnerability

  • CVE-2021-28440HigApr 13, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2021-27072HigApr 13, 2021
    risk 0.46cvss 7.0epss 0.01

    Win32k Elevation of Privilege Vulnerability

  • CVE-2021-27055HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.02

    Microsoft Visio Security Feature Bypass Vulnerability

  • CVE-2021-26873HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows User Profile Service Elevation of Privilege Vulnerability

  • CVE-2021-26866HigMar 11, 2021
    risk 0.46cvss 7.1epss 0.01

    Windows Update Service Elevation of Privilege Vulnerability

  • CVE-2021-26863HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.12

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2021-26862HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2021-24095HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.01

    DirectX Elevation of Privilege Vulnerability

  • CVE-2021-1729HigMar 11, 2021
    risk 0.46cvss 7.1epss 0.01

    Windows Update Stack Setup Elevation of Privilege Vulnerability

  • CVE-2021-24087HigFeb 25, 2021
    risk 0.46cvss 7.0epss 0.00

    Azure IoT CLI extension Elevation of Privilege Vulnerability

  • CVE-2021-1639HigFeb 25, 2021
    risk 0.46cvss 7.0epss 0.02

    Visual Studio Code Remote Code Execution Vulnerability

  • CVE-2021-1709HigJan 12, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2021-1682HigJan 12, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2020-17089HigDec 10, 2020
    risk 0.46cvss 7.1epss 0.03

    Microsoft SharePoint Elevation of Privilege Vulnerability

  • CVE-2020-17057HigNov 11, 2020
    risk 0.46cvss 7.0epss 0.02

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2020-17007HigNov 11, 2020
    risk 0.46cvss 7.0epss 0.01

    Windows Error Reporting Elevation of Privilege Vulnerability

  • CVE-2020-16998HigNov 11, 2020
    risk 0.46cvss 7.0epss 0.01

    DirectX Elevation of Privilege Vulnerability

  • CVE-2020-16977HigOct 16, 2020
    risk 0.46cvss 7.0epss 0.03

    A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on…

  • CVE-2020-16969HigOct 16, 2020
    risk 0.46cvss 7.1epss 0.03

    An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an…

  • CVE-2020-16934HigOct 16, 2020
    risk 0.46cvss 7.0epss 0.03

    An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to…

  • CVE-2020-16933HigOct 16, 2020
    risk 0.46cvss 7.0epss 0.03

    A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…

  • CVE-2020-16900HigOct 16, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted…

  • CVE-2020-16877HigOct 16, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions. To exploit…

  • CVE-2020-16876HigOct 16, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an…

  • CVE-2020-1308HigSep 11, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or…

  • CVE-2020-1245HigSep 11, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view,…

  • CVE-2020-16862HigSep 11, 2020
    risk 0.46cvss 7.1epss 0.03

    A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the…

  • CVE-2020-16857HigSep 11, 2020
    risk 0.46cvss 7.1epss 0.03

    A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim…

  • CVE-2020-16853HigSep 11, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…

  • CVE-2020-16852HigSep 11, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…

  • CVE-2020-16851HigSep 11, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status. To exploit this…

  • CVE-2020-0912HigSep 11, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially…

  • CVE-2020-0878MedKEVSep 11, 2020
    risk 0.46cvss 4.2epss 0.03

    A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1488HigAug 17, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to…

  • CVE-2020-1477HigAug 17, 2020
    risk 0.46cvss 7.0epss 0.03

    A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are…

  • CVE-2020-1473HigAug 17, 2020
    risk 0.46cvss 7.0epss 0.03

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by…

  • CVE-2020-1461HigJul 14, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

  • CVE-2020-1405HigJul 14, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1372.

  • CVE-2020-1364HigJul 14, 2020
    risk 0.46cvss 7.1epss 0.01

    A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'.

  • CVE-2019-3585HigJun 10, 2020
    risk 0.46cvss 7.0epss 0.00

    Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with…

  • CVE-2020-1244HigJun 9, 2020
    risk 0.46cvss 7.1epss 0.03

    A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120.

  • CVE-2020-1204HigJun 9, 2020
    risk 0.46cvss 7.1epss 0.01

    An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.

  • CVE-2020-1073HigJun 9, 2020
    risk 0.46cvss 8.1epss 0.09

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.

  • CVE-2020-1164HigMay 21, 2020
    risk 0.46cvss 7.0epss 0.02

    An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a…

  • CVE-2020-1151HigMay 21, 2020
    risk 0.46cvss 7.0epss 0.02

    An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a…

  • CVE-2020-1149HigMay 21, 2020
    risk 0.46cvss 7.0epss 0.02

    An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a…

  • CVE-2020-1143HigMay 21, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;…

  • CVE-2020-1138HigMay 21, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker would first have…

  • CVE-2020-1132HigMay 21, 2020
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability,…

Page 150 of 314